Skip to main content
RESEARCH • OPEN SOURCE • EXPERIMENTATION

Researching
what comes next.

Applied cybersecurity research & open-source engineering

Cyravex Labs explores cybersecurity, AI, detection, automation, deception, and emerging digital systems through authentic research, open-source tools, and experimental technology.

Authentic technical researchOpen-source contributionsZero marketing fluff
Core Focus Areas

Active Research Themes

The technical questions and security engineering domains actively explored by Cyravex Labs.

AI Safety & Non-Deterministic Security

Investigating prompt injection defense-in-depth, vector store poisoning mitigation, and autonomous agent sandboxing.

API & Microservice Authorization

Developing novel heuristics to detect broken object-level authorization (BOLA) and multi-tenant isolation failures in distributed architectures.

Detection Engineering & Deception

Engineering high-fidelity tripwires, decoy credentials, and automated detection rule pipelines that minimize alert fatigue.

Secure Software Architecture

Exploring pragmatic patterns that embed authentication, cryptographic hygiene, and least privilege into modern development frameworks.

Tools & Experiments

Featured Projects & Open-Source Tooling

Real tools and prototypes built to solve challenging cybersecurity and software engineering problems.

View GitHub Organization
Active ResearchAI SECURITY EXPERIMENT

PromptShield: RAG Context Isolation Benchmark

Research Question:

"Can indirect prompt injections be reliably neutralized at the vector database retrieval stage through context token partitioning?"

Purpose & Scope:

Evaluating multi-layer sanitization techniques to prevent retrieved untrusted documents from executing unauthorized tool calls.

Limitations: Focuses on retrieval-augmented generation architectures; direct chat prompt evaluation is excluded from current benchmark runs.
PythonLangChainVector DBsOpenAI
Repo
Beta PrototypeOPEN-SOURCE TOOL

BOLA-Hunter: GraphQL Authorization Analyzer

Research Question:

"How can deep AST inspection identify field-level authorization omissions in multi-role GraphQL schemas automatically?"

Purpose & Scope:

An automated security analysis utility that parses GraphQL schema definitions and tests cross-tenant IDOR/BOLA authorization matrix states.

Limitations: Requires introspectable schema or schema SDL file; stateful mutation authorization testing requires manual test cases.
GoGraphQL ASTHTTP/2
Repo
ExperimentalDECEPTION EXPERIMENT

CanaryTrace: Cloud Deception Token Generator

Research Question:

"What is the optimal latency and signal-to-noise ratio for deployed fake IAM credentials during adversary reconnaissance?"

Purpose & Scope:

A lightweight infrastructure-as-code module that provisions deceptive decoy IAM roles, fake API keys, and monitored S3 buckets to trigger high-fidelity alerts.

Limitations: Intended strictly for defensive deception monitoring within private cloud environments.
TerraformAWS LambdaGoCloudTrail
Repo
CYRAVEX SECURITY

Apply Research Insights to Your Infrastructure

Want to test your applications or AI architectures against the latest vulnerabilities explored in Cyravex Labs? Request a penetration test or AI safety review.

Explore Cyravex Security
CYRAVEX ENGINEERING

Build Systems Powered by Modern Tech

Need secure, scalable web platforms, internal business portals, or AI workflow automation engineered from the ground up?

Explore Cyravex Engineering
DIRECT SENIOR ENGAGEMENT

Interested in Technical Collaboration or Research?

Cyravex Labs welcomes collaboration with researchers, open-source contributors, and technical partners.

Confidential NDA guaranteed • Written Rules of Engagement • Rapid Proposal Response